Todd Schiller

CEO, PixieBrix

human

Misappropriation of Redeemable Value - AR4

A subject abuses authorized access to create, issue, increase, transfer, or redeem value-bearing instruments or account-based benefits without a legitimate business purpose or required approval. Redeemable value may include gift cards, promotional codes, vouchers, account credits, loyalty balances, refund credits, service credits, or similar benefits that can be exchanged for goods, services, discounts, or financial advantage. The subject may direct the value to themselves, friends, family members, associates, colluding customers, or other external parties. The value may be provided without payment, sold, exchanged, or otherwise used for personal or third-party gain. The subject may conceal the activity by using fictitious justifications, linking issuance to unrelated customer records, splitting value across multiple low-value transactions, remaining below approval thresholds, or repeatedly reissuing credits or codes.
human

Fraudulent Refund Issuance - AR4

A subject abuses authorized access to create, approve, increase, duplicate, or redirect a refund without a legitimate business basis or required authorization. The subject may issue the refund to themselves, a friend, family member, associate, colluding customer, or another external party. This may involve refunding a transaction that did not occur, issuing a refund where the goods or services remain valid, refunding more than the original amount, processing the same refund multiple times, or redirecting the proceeds to a payment method or account controlled by an unauthorized recipient. The subject may conceal the infringement by creating fictitious customer complaints, manipulating return or cancellation records, using unrelated customer accounts, bypassing approval thresholds, dividing the value across multiple refunds, or recording false reasons for the transaction.
human

Browser Print Restriction - PV093

Organizations should restrict browser-native print functionality within sensitive web applications, internal portals, administrative consoles, reporting platforms, and other browser-delivered tools where printing is not required for an approved business purpose. Browser printing can allow a subject to collect information without using the application’s normal download or export functions. The subject may use the browser print menu, keyboard shortcuts, print preview, print-to-PDF, a physical printer, or another virtual printer to convert displayed content into a consolidated and portable output. The control should ensure that browser printing cannot produce a usable unauthorized copy of protected information. Depending on operational requirements, organizations should:Block browser print and print preview for designated applications, pages, records, or data classifications.Prevent protected content from appearing in physical print output, print-to-PDF output, or output sent to other virtual printers.Permit controlled printing only where required, with protected content removed, masked, redacted, limited to approved fields, or replaced with a blank page or access-denied notice.Prevent alternate printable views, report-rendering endpoints, or document-generation routes from reproducing the same protected information.Record attempted and completed browser print actions, including the subject identity, application, page or record accessed, timestamp, requested output method, and control outcome. The restriction should be enforced through the web application, enterprise-managed browser, browser extension, browser security platform, or remote browser isolation service. Hiding a print button or suppressing a single keyboard shortcut is insufficient where the browser or application can still render the content through another print path.